Reference

istana 2000 Privacy Policy Explained

Clear rules for your account, device and wallet data are at the centre of the istana 2000 Privacy Policy.

Account recordsWallet statusDevice choicesPolicy contact
istana 2000 istana 2000 Privacy Policy Explained
HELP WITH PRIVACY

Where To Ask About Your Data

A direct support route helps you resolve a Privacy Policy question without searching through unrelated account pages.

Account access Use the support route shown beside your account and cashier path when you need to ask about phone verification, a login record or a data request. We will ask for enough account detail to locate the record, but not your password.
Wallet records For a DANA, OVO, GoPay or QRIS reference, include the transaction date and the visible receipt code rather than private wallet credentials. We use those details to check the relevant record and explain how the Privacy Policy treats it.
Policy requests Send a correction, access or deletion question through the policy contact path linked from your account. We may confirm your registered phone before discussing personal data, so a request is matched to the right account.
HOW WE HANDLE DATA

Privacy Controls Around Your Account

The Privacy Policy works alongside the account steps you already use: phone verification before account access, wallet-status checks during a payment event, and sign-in records when your device reaches the lobby.

Account security

Phone verification helps us connect an account request with the person who controls the registered number. Login time, device type and session signals may be checked when access looks unusual, while your password remains yours to protect.

Payment references

We retain the reference needed to trace a DANA, OVO, GoPay, QRIS, bank transfer or virtual account event. The reference helps us answer a receipt question without requiring the full credentials held by your bank or wallet.

Cookies and storage

Cookies and similar device storage can keep your session active, remember a selected page and help us understand whether a login step loaded correctly. You can manage browser storage through your device settings, although some account functions may then need another sign-in.

Mobile behaviour

On a phone, the policy can relate to browser type, session timing and the path from login to the lobby. We use those signals to diagnose a failed page or repeated sign-in, not to request access to unrelated files on your device.

Retention periods

We keep each category only for the period needed for its stated purpose, account support, security checks or a legal duty. A receipt record and a short-lived session signal therefore may not follow the same retention period.

Change requests

You can ask us to correct an inaccurate contact detail, explain a stored record or remove data when no continuing reason requires it. We may need phone confirmation and can retain a small request record so the outcome is traceable.

Privacy Policy Questions You May Have

These Privacy Policy answers focus on the account and payment records you are most likely to ask about before opening an account. We keep the wording direct so you can understand the data path behind phone verification, mobile sign-in, wallet receipts and support requests. If your question is not covered, use the policy contact path attached to your account.

The Privacy Policy covers account details, phone verification, login and device signals, support messages, cookie storage and payment references. It explains why we use each category, how long it may be kept, and how you can request access, correction or removal where the applicable rules allow.

Phone verification connects account access and privacy requests with the registered account holder. It also helps us investigate a sign-in that does not match your usual session. We do not need your password or full DANA, OVO, GoPay or QRIS credentials for this check.

Yes. The Privacy Policy covers the reference, date, amount status and account link needed to investigate a DANA or QRIS event. We may handle similar references for OVO, GoPay, bank transfer and virtual account activity, while the wallet or bank keeps its own credential records.

Use the policy contact path shown in your account and state whether you want access, correction or an explanation. Include your registered phone number and the relevant record date. We may confirm your identity before responding, and we will explain any part that cannot be changed.

Cookies and device storage can preserve a login session, remember a page choice or help diagnose a failed lobby load. Your browser settings let you clear or restrict them. If you do, the account may ask you to sign in again or reload the payment-status page.

There is not one identical period for every record. We keep account, security, support and payment references only while needed for their stated purpose, account support or a legal duty. A short-lived mobile session signal may be removed sooner than a transaction reference.

You can ask us to delete personal data when no continuing service, security or legal reason requires retention. Send the request through your account contact path. Eligibility depends on local law, and we may keep a limited record of the request and its outcome.